fix(gitflow): every autopush reader fails closed and names an invalid value

Run D1 of manual-push mode (BDR-114). `git config --bool --default true
gitflow.autopush` only covered a MISSING key: an unparseable value made
git die with empty output, the `= false` test failed, and every push ran
again. A typo on a work machine silently re-enabled the pushes it was
meant to stop.

- lib/gitflow.sh: `_gitflow_push_off` reads the mode through the lib
  verb (`push-mode`); anything but `auto` is push-off, and the verb's
  stderr line names an invalid value during start/finish.
- Emitted post-commit/post-merge hooks (POSIX sh, standalone): push only
  when the key reads `true` or is unset; `false` exits quietly; any
  other result prints one stderr line ("NOT pushed, treated as manual
  push mode") and exits 0. Mirrors gitflow_push_mode.
- .githooks/ and githooks/ regenerated files-only through `emit-hook`
  (no config read or write; .git/config hash unchanged).
- hooks/unpushed-guard.sh: mode from the lib verb (absolute lib path
  resolved before any cd, no temp file); anything but auto is manual;
  the SessionStart line names an invalid or unreadable value.
- Tests: gitflow-test T18q block (invalid → start, hook and finish push
  nothing and say so; `true` → the hook pushes; emitted hook is
  POSIX-clean), unpushed-guard T14 rewritten.
This commit is contained in:
bchanot
2026-10-07 16:45:31 +02:00
parent e4bc6212ef
commit 472cccbc52
8 changed files with 98 additions and 26 deletions
+24
View File
@@ -406,6 +406,30 @@ div_err="$WORK/div.err"
div_out=$(gitflow_start feature div 2>"$div_err")
chk "T18l diverged base → warns on stderr, stdout stays the branch name" "[ \"$div_out\" = feature/div ] && grep -q 'behind origin/develop' \"$div_err\" && git rev-parse --verify -q refs/heads/feature/div >/dev/null"
echo "T18q — fail closed: unparseable gitflow.autopush → nothing pushes, named (BDR-114)"
newrepo badval; echo a>a; hookon; gitflow_init >/dev/null 2>&1
bare="$WORK/badval.git"; git init -q --bare "$bare"; git remote add origin "$bare"
git push -q -u origin main develop 2>/dev/null
git config gitflow.autopush flase
gitflow_start feature bad >/dev/null 2>"$WORK/q1.err"
chk "T18q1 start → branch local, not on origin, value named" "git rev-parse --verify -q refs/heads/feature/bad >/dev/null && ! git ls-remote --exit-code --heads origin feature/bad >/dev/null 2>&1 && grep -q 'not a boolean' \"$WORK/q1.err\""
echo b>b.txt; git add b.txt; git commit -q -m b 2>"$WORK/q2.err"
chk "T18q2 commit → not pushed, hook says NOT pushed" "! git ls-remote --exit-code --heads origin feature/bad >/dev/null 2>&1 && grep -q 'NOT pushed' \"$WORK/q2.err\""
dev_before=$(git -C "$bare" rev-parse develop)
gitflow_finish >/dev/null 2>&1; q_rc=$?
chk "T18q3 finish → merged locally, origin develop unchanged" "[ $q_rc -eq 0 ] && [ \"\$(git -C \"$bare\" rev-parse develop)\" = \"$dev_before\" ] && ! git rev-parse --verify -q refs/heads/feature/bad >/dev/null"
git config gitflow.autopush true
gitflow_start feature good >/dev/null 2>&1
echo g>g.txt; git add g.txt; git commit -q -m g 2>/dev/null
chk "T18q4 true → post-commit pushed (tips equal)" '[ "$(git rev-parse HEAD)" = "$(git -C "$bare" rev-parse feature/good)" ]'
_gitflow_emit_push_hook post-commit > "$WORK/pc.sh"
chk "T18q5a emitted hook carries the rc:value case" "[ -s \"$WORK/pc.sh\" ] && grep -qF 'case \"\$rc:\$v\"' \"$WORK/pc.sh\""
if command -v shellcheck >/dev/null 2>&1; then
chk "T18q5 emitted hook is POSIX-clean" "shellcheck -s sh \"$WORK/pc.sh\""
else
ok "T18q5 skipped (no shellcheck)"
fi
echo "T19 — installed hooks == emitted hooks in the config repo (LRN-114 drift gate)"
if [ -d "$HERE/../.githooks" ]; then
chk "T19a pre-commit installed == emitted" 'diff -q <(_gitflow_emit_pre_commit) "$HERE/../.githooks/pre-commit" >/dev/null'
+19 -9
View File
@@ -97,12 +97,14 @@ gitflow_push_mode() {
# ── start ────────────────────────────────────────────────────────────────────
# rc 0 when pushing is off: GITFLOW_NO_PUSH=1 (throwaway test repos) or
# gitflow.autopush=false (manual-push mode, human-set: work machine, foreign
# clone). The single reader of both flags for the lib's own push sites.
# rc 0 when pushing is off: GITFLOW_NO_PUSH=1 (throwaway test repos), or
# gitflow.autopush not readable as `true`/unset — manual-push mode (false,
# human-set) AND fail closed on an unparseable value or a config read
# failure (BDR-114). The verb's stderr passes through: it names an invalid
# value and is silent for auto/manual. Single reader for the lib's push sites.
_gitflow_push_off() {
[ "${GITFLOW_NO_PUSH:-0}" = 1 ] && return 0
[ "$(git config --bool --default true gitflow.autopush)" = false ]
[ "$(gitflow_push_mode)" != auto ]
}
# gitflow_start <type> <name> → checkout -b <type>/<name> from the correct base.
@@ -192,8 +194,9 @@ gitflow_merged_into_base() {
return 1
}
# _gitflow_note_remote_left <br> → manual mode never deletes origin/<br>; say
# so when a remote-tracking ref shows a copy exists (no network call).
# _gitflow_note_remote_left <br> → push off (manual mode or invalid value) never
# deletes origin/<br>; say so when a remote-tracking ref shows a copy exists
# (no network call).
_gitflow_note_remote_left() {
local br="$1"
gitflow_protected_base "$br" && return 0
@@ -203,7 +206,7 @@ _gitflow_note_remote_left() {
# _gitflow_delete_remote <br> → remove origin/<br> once the LOCAL copy is gone.
# Same contract as the pushes (BDR-095): best effort, warn never fail; skipped
# under GITFLOW_NO_PUSH=1, gitflow.autopush=false or no origin. The REMOTE tip
# when push is off (see _gitflow_push_off) or no origin. The REMOTE tip
# is re-checked against develop/main before the delete: a commit pushed from
# elsewhere that never reached a base (or that this clone has never fetched)
# keeps the remote branch alive, loudly. Never a base, by construction and by
@@ -507,8 +510,15 @@ cat <<'HOOK'
# holds. Never fails the commit: no origin / offline / refused → warning only.
# Opt out for one command with GITFLOW_NO_PUSH=1 (throwaway repos, tests).
[ "${GITFLOW_NO_PUSH:-0}" = 1 ] && exit 0
# Per-repo opt-out (no push rights on a foreign clone): git config gitflow.autopush false
[ "$(git config --bool --default true gitflow.autopush)" = false ] && exit 0
# Manual-push mode (human-set): git config gitflow.autopush false. Fail closed:
# an unparseable value or a config read failure also means "no push", named.
# Mirrors gitflow_push_mode (lib/gitflow.sh); arms pinned by T18b/T18h/T18q2/T18q4.
v=$(git config --bool gitflow.autopush 2>/dev/null); rc=$?
case "$rc:$v" in
0:true|1:*) ;;
0:false) exit 0 ;;
*) echo "gitflow $hook: gitflow.autopush unreadable (git rc $rc) — NOT pushed, treated as manual push mode; fix the value by hand" >&2; exit 0 ;;
esac
git remote get-url origin >/dev/null 2>&1 || exit 0
br=$(git symbolic-ref --short -q HEAD 2>/dev/null) || exit 0 # detached HEAD — nothing to track
if command -v timeout >/dev/null 2>&1; then t="timeout ${GITFLOW_PUSH_TIMEOUT:-30}"; else t=""; fi
+4 -2
View File
@@ -66,8 +66,10 @@ git config gitflow.autopush flase
echo i>i; git add i; git commit -q -m i
out=$(fire SessionStart "$PWD")
check T14-invalid-named "$(has "$out" "not a boolean")" yes
check T14-invalid-treated-auto "$(has "$out" "unpushed work")" yes
check T14-invalid-stop-auto "$(has "$(fire Stop "$PWD")" "1 commit(s)")" yes
check T14-invalid-prefix "$(has "$out" "ℹ manual push mode:")" yes
check T14-invalid-treated "$(has "$out" "treated as manual")" yes
check T14-invalid-no-warn "$(has "$out" "unpushed work")" no
check T14-invalid-stop-silent "$(fire Stop "$PWD")" silent
git config --unset gitflow.autopush
check T15-unset-auto-intact "$(has "$(fire Stop "$PWD")" "1 commit(s)")" yes
git config gitflow.autopush false; git remote remove origin